SOC 1 Audit Reports

Organizations that provide services affecting their clients’ financial reporting often need independent assurance that their internal controls are designed and operating effectively. Packer Thomas performs SOC 1 examinations to help service organizations demonstrate the reliability of their financial reporting controls, strengthen client confidence, and meet customer and regulatory expectations.

Whether you’re obtaining your first SOC 1 report or preparing for an annual examination, our professionals provide practical guidance throughout the engagement while helping your organization understand and improve its control environment.

Independent Assurance

We perform independent examinations of your internal controls that impact your customers' financial reporting.

Stronger Internal Controls

We identify opportunities to improve processes while reducing risk and strengthening internal controls.

Client & Auditor Confidence

Provide customers and their auditors with assurance that your controls are designed and operating effectively.

Meet Requirements & Drive Growth

Meet customer, regulatory, and contractual requirements while positioning your organization for success.

What Is a SOC 1 Report?

A SOC 1 report is an independent examination performed under standards established by the American Institute of Certified Public Accountants (AICPA) that evaluates the controls at a service organization that are relevant to its customers’ internal control over financial reporting. SOC 1 examinations are performed in accordance with Statement on Standards for Attestation Engagements No. 18 (SSAE 18), the AICPA standard governing these engagements. According to the AICPA’s guidance on SOC 1 reports, these examinations are designed specifically for service organizations whose controls may affect the financial statements of their customers.

SOC 1 reports help user entities and their auditors understand whether appropriate controls are designed and operating effectively, providing valuable assurance over processes that impact financial reporting. They are commonly requested from organizations that process financial transactions, maintain accounting records, administer payroll or employee benefits, manage investment activities, or provide other outsourced services that directly influence their customers’ financial reporting.

Auditor reviewing documentation and financial records during a SOC 1 audit report engagement.

Who Needs a SOC 1 Report?

Organizations whose services influence their clients’ financial reporting often benefit from obtaining a SOC 1 report. While not legally required, many customers, auditors, and business partners expect service organizations to provide independent assurance regarding their control environment.

Organizations that commonly obtain SOC 1 reports include:

  • Payroll service providers
  • Third-party accounting firms
  • Financial technology companies
  • Claims processing organizations
  • Benefits administrators
  • Data processing providers
  • Investment administrators
  • Other outsourced financial service providers

While these are among the most common organizations requiring SOC 1 examinations, Packer Thomas works with service organizations across a wide range of industries. Whether your organization supports manufacturing, healthcare, construction, nonprofit organizations, financial services, or another industry, we tailor each SOC 1 engagement to your services, systems, risks, and customer requirements.

Obtaining a SOC 1 report can simplify customer audits, satisfy contractual requirements, and strengthen trust with current and prospective clients.

What is SSAE 18?

SSAE 18 is the AICPA attestation standard that governs SOC 1 examinations. It establishes requirements for how service auditors evaluate and report on controls relevant to a service organization’s customers’ financial reporting.

SOC 1 Type I Reports vs. SOC 1 Type II Reports

Both SOC 1 report types evaluate controls relevant to financial reporting, but they differ in what is examined.

Report Type What It Evaluates Best For
SOC 1 Type I
Reviews the design of controls at a specific point in time.
Organizations obtaining their first SOC report or needing assurance quickly.
SOC 1 Type II
Reviews both the design and operating effectiveness of controls over a defined period.
Organizations demonstrating ongoing control effectiveness to customers and auditors.

Many organizations begin with a Type I examination before transitioning to a Type II report as their control environment matures.

Which SOC Report Is Right for You?

Not every organization needs the same SOC report. The right examination depends on the services you provide and what your customers need to verify.

Report Best For Common Industries & Organizations Primary Focus
SOC 1
Service organizations that affect their customers’ financial reporting
Payroll providers, benefits administrators, fintech companies, investment administrators, claims processors, outsourced accounting providers
Internal controls over financial reporting
Organizations that store, process, or transmit customer data
SaaS companies, cloud service providers, managed IT providers, data centers, healthcare technology, cybersecurity firms
Security, availability, processing integrity, confidentiality, and privacy
Organizations that want to publicly demonstrate their commitment to security
Technology companies, SaaS providers, cloud platforms, managed service providers, and other businesses that have completed a SOC 2 examination
Public-facing summary of a SOC 2 report without detailed testing results

Not sure which report fits your organization? Our professionals can help determine whether a SOC 1 Report, SOC 2 Report, or SOC 3 Report best aligns with your customers’ expectations and compliance requirements.

What Systems and Controls Are Evaluated?

Each SOC 1 engagement is tailored to the services your organization provides. During the examination, we evaluate the controls that support accurate and reliable financial reporting for your customers.

Examples of controls that may be evaluated include:

  • Transaction processing
  • Access controls
  • Change management
  • Data integrity
  • Reconciliations
  • Segregation of duties
  • System monitoring
  • Incident management
  • Backup and recovery procedures
  • Financial reporting processes

The specific scope of the engagement depends on your organization’s services, systems, and the risks that could affect your customers’ financial reporting.

Benefits of a SOC 1 Report

A SOC 1 report provides independent assurance that your organization has established appropriate controls over services affecting your customers’ financial reporting. Beyond meeting customer expectations, a SOC 1 examination can strengthen internal processes, reduce risk, and reinforce confidence in your organization.

Benefit How Your Organization Benefits
Increased Client Confidence
Demonstrates an independent evaluation of your internal controls.
Simplified Customer Audits
Provides customers and their auditors with assurance, reducing duplicate audit requests.
Stronger Internal Controls
Identifies opportunities to improve processes and reduce operational risk.
Competitive Advantage
Shows prospective customers your commitment to accountability and quality.
Regulatory & Contractual Support
Helps satisfy customer, industry, and contractual requirements.
Ongoing Process Improvement
Encourages continuous monitoring and enhancement of your control environment.

Why Choose Packer Thomas for SOC 1 Audit Reports?

Successfully completing a SOC 1 examination requires more than checking compliance boxes. It requires a thorough understanding of your organization’s operations, the risks affecting your customers’ financial reporting, and the controls that support reliable financial processes.

Packer Thomas provides practical guidance throughout the SOC 1 examination process, helping organizations prepare for the engagement, strengthen their control environment, and communicate effectively with customers and auditors. When additional expertise is needed, our professionals collaborate with specialists in Accounting & Attest Services and Information Technology Consulting to deliver coordinated solutions that support your long-term compliance and business objectives.

Our SOC Team

Principal & Director of Information Technology Consulting

Areas of Expertise:

  • SOC Engagements
  • Acumatica – The Cloud ERP
  • Sage 300 & Sage CRM
  • Third Party Applications for Acumatica and Sage 300
  • Information Systems Security Reviews
  • System Evaluation and Implementation/Project Management
  • QuickBooks

Jeffrey R. Sheets, CPA

Consultant

Areas of Expertise:

  • Information Security Audits
  • PCI DSS Audit
  • Information Security Program Development
  • Cloud Security
  • GDPR, NIST 800-53, ISO 27001, and Hitrust

William Long, CISA, CISM, CGEIT, GSEC, GSNA, CSF, PCI QSA

Request Our Services

Name(Required)

FAQ

About Packer Thomas

Packer Thomas is a full-service CPA and business advisory firm serving businesses, nonprofit organizations, government entities, and individuals throughout Ohio and beyond. Since 1923, our professionals have provided practical guidance designed to help clients navigate complex financial, operational, technological, and regulatory challenges.

Our services include accounting and attest, tax consulting, client accounting services, business valuations, forensic accounting, IT consulting, and SOC examinations. By bringing together professionals from multiple disciplines, we provide coordinated solutions tailored to each client’s industry, goals, and risk environment.

With offices in Canfield and New Castle, Ohio, Packer Thomas combines the capabilities of an experienced advisory firm with responsive, personalized service. Contact us to learn how our team can help your organization strengthen internal controls, meet customer expectations, and prepare for a successful SOC 1 examination.